{"id":15498,"date":"2026-09-18T05:32:34","date_gmt":"2026-09-18T05:32:34","guid":{"rendered":"https:\/\/www.examlabs.com\/certification\/?p=15498"},"modified":"2026-09-18T05:32:34","modified_gmt":"2026-09-18T05:32:34","slug":"isc-cissp-practice-test-questions-and-exam-dumps-part11-q201-220","status":"publish","type":"post","link":"https:\/\/www.examlabs.com\/certification\/isc-cissp-practice-test-questions-and-exam-dumps-part11-q201-220\/","title":{"rendered":"ISC CISSP Practice Test Questions and Exam Dumps Part11 Q201-220"},"content":{"rendered":"<h1><\/h1>\n<h2><b>View Full <\/b><a href=\"https:\/\/www.examlabs.com\/cissp-exam-dumps\"><b>ISC CISSP Exam Dumps<\/b><\/a><b> and Practice Test Dumps.<\/b><\/h2>\n<p>&nbsp;<\/p>\n<h3><b>Question 201<\/b><\/h3>\n<p><b>Which process ensures that proposed changes to production systems are formally reviewed, approved, tested, and documented before implementation?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Data classification<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Change management<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Incident eradication<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Asset disposal<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Change management provides a controlled process for modifying systems, applications, networks, and configurations. Proposed changes should normally be documented, assessed for security and operational impact, tested when appropriate, approved by authorized personnel, and implemented according to established procedures. Change management reduces the likelihood that unauthorized or poorly tested modifications will introduce vulnerabilities or disrupt critical services. Emergency changes may follow an expedited process but should still be documented and reviewed afterward. Effective change management also supports accountability, configuration control, and reliable system maintenance.<\/span><\/p>\n<h3><b>Question 202<\/b><\/h3>\n<p><b>A security administrator wants to ensure that only authorized personnel can modify firewall rules. Which control is most appropriate?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Role-based access control<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Data retention<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Network address translation<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Environmental monitoring<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Role-based access control assigns permissions according to defined job responsibilities. Firewall administration can be restricted to an authorized network security role while preventing ordinary users from changing security rules. This supports least privilege and reduces the risk of unauthorized or accidental configuration changes. Administrative roles should receive only the permissions necessary for their responsibilities, and privileged actions should be logged and monitored. Organizations may also use multifactor authentication, separation of duties, approval workflows, and configuration management to provide additional protection for critical security infrastructure.<\/span><\/p>\n<h3><b>Question 203<\/b><\/h3>\n<p><b>Which security concept requires an organization to maintain accurate records showing who performed a particular administrative action?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Confidentiality<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Availability<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Accountability<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Data minimization<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Accountability provides the ability to associate actions with identifiable users, systems, or processes. Organizations can support accountability through unique user accounts, strong authentication, authorization controls, audit logging, and monitoring. Shared administrative accounts can weaken accountability because actions cannot easily be attributed to a specific individual. Logs should record relevant details such as user identity, timestamp, action, and affected resource when appropriate. Protecting logs from unauthorized alteration is also important because audit records may be needed for investigations, compliance activities, and incident response.<\/span><\/p>\n<h3><b>Question 204<\/b><\/h3>\n<p><b>Which security architecture approach divides a network into separate zones to limit the movement of an attacker after a system is compromised?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Network segmentation<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Data compression<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Key escrow<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Password synchronization<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Network segmentation divides a network into separate security zones or segments and controls communication between them. This can limit lateral movement when an attacker compromises one system. For example, user workstations, servers, databases, guest devices, and management systems can be placed into different segments with restrictive communication rules. Segmentation can also reduce the scope of security incidents and support regulatory requirements. It should be implemented with appropriate access controls and monitoring because poorly configured segmentation may provide a false sense of security.<\/span><\/p>\n<h3><b>Question 205<\/b><\/h3>\n<p><b>Which security control helps prevent sensitive information from leaving an organization through email, cloud storage, removable media, or other communication channels?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Data loss prevention<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Network time protocol<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">RAID<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Load balancing<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Data loss prevention, or DLP, helps identify and prevent unauthorized disclosure or transmission of sensitive information. DLP solutions can monitor endpoints, email, network traffic, cloud services, and removable storage for information matching defined policies. Organizations can create rules based on data classifications, patterns, keywords, file characteristics, or other indicators. Depending on the implementation, DLP may alert security teams, block transmission, quarantine content, or require user justification. Effective DLP requires accurate policies and should be balanced against legitimate business workflows to reduce false positives.<\/span><\/p>\n<h3><b>Question 206<\/b><\/h3>\n<p><b>Which protocol is commonly used to synchronize clocks across networked systems so that security logs have consistent timestamps?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DNS<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">NTP<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">LDAP<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">FTP<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Network Time Protocol, or NTP, synchronizes system clocks across networked devices. Accurate and consistent time is important for security monitoring because analysts often correlate events from multiple systems using timestamps. Incorrect system clocks can make incident timelines difficult to reconstruct and may interfere with authentication protocols or certificate validation. Organizations should use trusted time sources and protect time synchronization infrastructure appropriately. Security-sensitive environments may also monitor synchronization failures or significant clock deviations to identify operational problems and maintain reliable audit records.<\/span><\/p>\n<h3><b>Question 207<\/b><\/h3>\n<p><b>Which protocol commonly provides centralized authentication, authorization, and accounting services for network access?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">RADIUS<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">SMTP<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DNSSEC<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">SFTP<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">RADIUS, or Remote Authentication Dial-In User Service, provides centralized authentication, authorization, and accounting for many types of network access. It is commonly used with wireless networks, VPN services, and network access control systems. Centralizing authentication can simplify administration and provide consistent access policies across multiple devices. RADIUS deployments should use appropriate security protections and strong authentication mechanisms. RADIUS is distinct from LDAP, which is primarily a directory access protocol, although the two technologies can work together in an authentication architecture.<\/span><\/p>\n<h3><b>Question 208<\/b><\/h3>\n<p><b>Which protocol provides secure directory access by protecting LDAP communications with TLS?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">HTTP<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">LDAPS<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Telnet<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">TFTP<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">LDAPS refers to LDAP communication protected using TLS, providing encryption and protection against interception during directory operations. LDAP directories commonly store information such as user identities, groups, and organizational attributes and may participate in authentication and authorization processes. Protecting directory traffic is important because intercepted credentials or sensitive directory information could support further attacks. Organizations should use secure configurations, valid certificates, strong authentication, and appropriate access controls. LDAP itself should not be assumed to provide confidentiality unless an appropriate secure transport mechanism is implemented.<\/span><\/p>\n<h3><b>Question 209<\/b><\/h3>\n<p><b>Which technology provides a secure encrypted tunnel through an untrusted network such as the public Internet?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">VPN<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">VLAN<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">NAT<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Proxy ARP<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A virtual private network, or VPN, creates a protected communication path across an untrusted network. Depending on the technology, a VPN can provide confidentiality, integrity, authentication, and secure remote connectivity. Organizations commonly use VPNs to connect remote users or branch networks to corporate resources. Security depends on the underlying protocol, cryptographic configuration, authentication methods, endpoint security, and access policies. A VPN does not automatically make an endpoint trustworthy, so organizations should combine VPN access with least privilege, multifactor authentication, monitoring, and appropriate device security controls.<\/span><\/p>\n<h3><b>Question 210<\/b><\/h3>\n<p><b>Which technology translates private internal IP addresses into public addresses when systems communicate with external networks?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DNS<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">NAT<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">NTP<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">LDAP<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Network Address Translation, or NAT, translates IP addresses between different addressing domains. A common implementation allows multiple private internal systems to communicate with external networks by using one or more public IP addresses. NAT can reduce direct exposure of internal addresses, although it should not be considered a replacement for a firewall or other security controls. NAT may also conserve IPv4 address space. Organizations should understand that address translation alone does not provide comprehensive protection because applications and network services can still be attacked through permitted connections.<\/span><\/p>\n<h3><b>Question 211<\/b><\/h3>\n<p><b>Which security technology filters web application requests and can block attacks such as SQL injection and cross-site scripting?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Web application firewall<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Network switch<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Hardware security module<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">File integrity monitor<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A web application firewall, or WAF, monitors and filters HTTP or HTTPS traffic directed toward web applications. It can use rules and inspection techniques to identify and block common web attacks, including SQL injection, cross-site scripting, malicious requests, and certain application-layer abuse patterns. A WAF can provide an additional security layer but should not replace secure application development, input validation, authentication, authorization, and vulnerability management. Proper tuning is important because overly restrictive rules may block legitimate application traffic while insufficient rules may allow attacks through.<\/span><\/p>\n<h3><b>Question 212<\/b><\/h3>\n<p><b>Which security device is specifically designed to inspect network traffic and actively block detected malicious activity?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Intrusion detection system<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Intrusion prevention system<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Security information and event management system<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Vulnerability scanner<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">An intrusion prevention system, or IPS, monitors network activity and can automatically block traffic identified as malicious. It may use signatures, protocol analysis, anomaly detection, behavioral techniques, or combinations of these methods. An IPS differs from an intrusion detection system because an IDS generally generates alerts without directly blocking the traffic. IPS rules require appropriate configuration and tuning because false positives can disrupt legitimate operations. Organizations should also maintain updated detection signatures and review alerts to ensure the system continues to provide effective protection.<\/span><\/p>\n<h3><b>Question 213<\/b><\/h3>\n<p><b>Which endpoint security technology is designed to continuously monitor devices and provide detection and response capabilities for suspicious activity?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">EDR<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">RAID<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DNSSEC<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">NAT<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Endpoint Detection and Response, or EDR, continuously monitors endpoint activity and collects information that can help identify suspicious behavior. EDR solutions may observe processes, files, network connections, user activity, and other endpoint events. Security teams can investigate alerts and, depending on the product, isolate compromised devices, terminate malicious processes, or perform other response actions. EDR provides broader visibility than traditional antivirus alone, although organizations still need patch management, secure configurations, application controls, and other endpoint protections. Proper tuning and skilled monitoring are important for effective use.<\/span><\/p>\n<h3><b>Question 214<\/b><\/h3>\n<p><b>Which malware type is capable of independently spreading from one vulnerable system to another without requiring a user to manually execute it on each target?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Trojan horse<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Worm<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Spyware<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Rootkit<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A worm is malware capable of self-propagation across systems, often by exploiting vulnerabilities or weaknesses in network services. Unlike a traditional virus, a worm does not necessarily require a user to execute an infected file on every new target. Worm outbreaks can spread rapidly and consume network resources while compromising large numbers of systems. Effective defenses include timely patching, network segmentation, endpoint protection, access controls, vulnerability management, and monitoring for abnormal network behavior. Organizations should also maintain incident response procedures for containing rapidly spreading malware.<\/span><\/p>\n<h3><b>Question 215<\/b><\/h3>\n<p><b>An attacker inserts malicious database commands into an application input field to manipulate backend database queries. What attack is being attempted?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Cross-site scripting<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">SQL injection<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Buffer overflow<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Directory traversal<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">SQL injection occurs when an attacker manipulates application input so that malicious SQL statements are incorporated into database queries. Successful exploitation can allow unauthorized access to information, modification or deletion of records, authentication bypass, or other harmful actions depending on the application&#8217;s privileges and database configuration. Parameterized queries or prepared statements are among the primary defenses against SQL injection. Input validation, least privilege for database accounts, secure coding practices, and security testing provide additional protection. Applications should never construct database queries by blindly concatenating untrusted input.<\/span><\/p>\n<h3><b>Question 216<\/b><\/h3>\n<p><b>A web application displays attacker-supplied script code in another user&#8217;s browser. Which vulnerability does this describe?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">SQL injection<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Cross-site scripting<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Command injection<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Race condition<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Cross-site scripting, or XSS, occurs when an application allows attacker-controlled content to execute as script in another user&#8217;s browser. Depending on the type and context, XSS can enable session theft, malicious page modification, credential harvesting, or unauthorized actions performed through the victim&#8217;s browser. Common defenses include context-appropriate output encoding, input validation, secure content security policies, and careful handling of untrusted content. Developers should understand the difference between reflected, stored, and DOM-based XSS because the attack mechanisms and appropriate defensive techniques can differ.<\/span><\/p>\n<h3><b>Question 217<\/b><\/h3>\n<p><b>Which vulnerability occurs when the outcome of a process depends on the timing or ordering of events that can be manipulated by an attacker?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Race condition<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">SQL injection<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Phishing<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Password spraying<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A race condition occurs when the security or correctness of a process depends on the timing or sequence of events. An attacker may attempt to manipulate the timing so that a system performs an action under one condition and then uses a changed condition during a later step. This can lead to authorization bypasses, inconsistent data, or other security problems. Developers can reduce race-condition risks through appropriate synchronization, atomic operations, locking mechanisms, secure transaction design, and careful validation of state changes. Security testing should consider concurrent operations where relevant.<\/span><\/p>\n<h3><b>Question 218<\/b><\/h3>\n<p><b>Which password-storage technique adds a unique random value to each password before hashing to make precomputed attacks more difficult?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Encryption<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Salting<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Tokenization<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Encoding<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Salting adds a unique random value to each password before the password is processed by a password-hashing function. A unique salt prevents identical passwords from producing identical stored hash values and makes precomputed rainbow-table attacks substantially less useful. Passwords should be processed using password-specific hashing algorithms designed to be computationally expensive, rather than relying on fast general-purpose hashes alone. Salts do not need to remain secret, but they should be stored with the corresponding password hash. Strong password storage also requires appropriate access controls and secure credential management.<\/span><\/p>\n<h3><b>Question 219<\/b><\/h3>\n<p><b>Which device or service is designed to prevent unauthorized devices from connecting to an organization&#8217;s internal network based on defined access policies?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Network access control<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Load balancer<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DNS resolver<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Proxy cache<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Network access control, or NAC, enforces policies governing which devices may connect to a network. NAC solutions can evaluate characteristics such as device identity, authentication status, security posture, operating system, or compliance state before granting access. Noncompliant devices may be denied access or placed into restricted remediation networks. NAC can help reduce the risk associated with unmanaged or compromised endpoints. Effective NAC deployments should be integrated with identity services, endpoint security, network infrastructure, and monitoring while ensuring that emergency and operational requirements are properly addressed.<\/span><\/p>\n<h3><b>Question 220<\/b><\/h3>\n<p><b>Which cryptographic device is specifically designed to securely generate, store, and use cryptographic keys while protecting them from unauthorized extraction?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Proxy server<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Hardware security module<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Network switch<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Load balancer<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A hardware security module, or HSM, is a specialized device designed to protect cryptographic keys and perform sensitive cryptographic operations in a controlled hardware environment. HSMs can support key generation, storage, signing, encryption, decryption, and other operations while providing mechanisms intended to prevent unauthorized key extraction. They are commonly used in payment systems, certificate authorities, enterprise key management, and other environments requiring strong protection of cryptographic material. Proper physical security, access control, key lifecycle management, backup procedures, and operational governance remain important even when HSMs are deployed.<\/span><\/p>\n<p>&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>View Full ISC CISSP Exam Dumps and Practice Test Dumps. &nbsp; Question 201 Which process ensures that proposed changes to production systems are formally reviewed, approved, tested, and documented before implementation? Data classification Change management Incident eradication Asset disposal Correct Answer: 2 Explanation Change management provides a controlled process for modifying systems, applications, networks, and [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":[],"categories":[1648,1647],"tags":[],"_links":{"self":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/15498"}],"collection":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/comments?post=15498"}],"version-history":[{"count":1,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/15498\/revisions"}],"predecessor-version":[{"id":15517,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/15498\/revisions\/15517"}],"wp:attachment":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/media?parent=15498"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/categories?post=15498"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/tags?post=15498"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}